First published: Fri Dec 01 2017(Updated: )
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the NetBIOS dissector could crash. This was addressed in epan/dissectors/packet-netbios.c by ensuring that write operations are bounded by the beginning of a buffer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/wireshark | 2.6.20-0+deb10u4 2.6.20-0+deb10u7 3.4.10-0+deb11u1 4.0.6-1~deb12u1 4.0.10-1 | |
Wireshark Wireshark | =2.2.0 | |
Wireshark Wireshark | =2.2.1 | |
Wireshark Wireshark | =2.2.2 | |
Wireshark Wireshark | =2.2.3 | |
Wireshark Wireshark | =2.2.4 | |
Wireshark Wireshark | =2.2.5 | |
Wireshark Wireshark | =2.2.6 | |
Wireshark Wireshark | =2.2.7 | |
Wireshark Wireshark | =2.2.8 | |
Wireshark Wireshark | =2.2.9 | |
Wireshark Wireshark | =2.2.10 | |
Wireshark Wireshark | =2.4.0 | |
Wireshark Wireshark | =2.4.1 | |
Wireshark Wireshark | =2.4.2 | |
Debian GNU/Linux | =8.0 | |
Debian GNU/Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17083 is considered a medium severity vulnerability that can cause crashes in the Wireshark application.
To fix CVE-2017-17083, update Wireshark to version 2.4.3 or later, or any of the patched versions listed in the advisory.
Versions of Wireshark from 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10 are affected by CVE-2017-17083.
The NetBIOS dissector component of Wireshark is impacted by CVE-2017-17083.
Using an affected version of Wireshark can lead to application crashes, making it unsafe to use until remediated.